CVE Tools

Разработчики призвали срочно исправить критическую уязвимость в GitLab

Хакер (xakep.ru)By Мария Нефёдова

Reported exploitedGitLab CEGitLab EE

Our summary

GitLab has released patches for a critical path traversal vulnerability identified as CVE-2026-85706, which carries a maximum CVSS score of 10. This flaw allows unauthenticated attackers to read arbitrary files on the server through the repository commits API, affecting GitLab Community Edition and Enterprise Edition versions from 18.7 up to 19.3.1.

Security researchers have observed active exploitation attempts in the wild shortly after the vulnerability was disclosed, making immediate remediation essential. In addition to CVE-2026-85706, the update also addresses CVE-2026-87719, a high-severity insecure deserialization issue in GitLab EE's GraphQL subscription serializer. Administrators are advised to upgrade to fixed versions 19.3.2, 19.2.6, or 19.1.8 immediately to protect against potential data exfiltration.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store